6.5
CVSSv2

CVE-2015-6395

Published: 12/12/2015 Updated: 13/09/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Cisco Prime Service Catalog 10.0, 10.0(R2), 10.1, and 11.0 does not properly restrict access to web pages, which allows remote malicious users to modify the configuration via a direct request, aka Bug ID CSCuw48188.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco prime service catalog 10.1_base

cisco prime service catalog 10.0_base

cisco prime service catalog 11.0_base

cisco prime service catalog 10.0\\(r2\\)_base

Vendor Advisories

A vulnerability in the web interface of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to perform limited configuration changes The vulnerability is due to missing access controls in some of the web pages that allow configuration changes An attacker could exploit this vulnerability by accessing the URLs of the affec ...